ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 205 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1471bd32-4b91-4351-957f-e0a497d471ec
< 4.3.0
HIGH 8.8 The WpEvently plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.9. This m… wordfence
1465dbb6-1ec3-425f-9b7e-6dff6b120606
< 5.2.0
HIGH 8.8 The RD Station plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.3.… wordfence
145deebd-1e15-4f8a-878c-9424c2cd9601
< 2.0.2
HIGH 8.8 The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up … wordfence
1432907e-bcd0-498f-9356-f269a252bc4b HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 1.9.22 for WordPress allow remot… wordfence
1404f034-2d1d-44b2-87e5-61f72f215417
< 2.6.7
HIGH 8.8 The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.… wordfence
13e7c4ab-7856-41a5-8cd9-4f8118af534d
< 3.0.102
HIGH 8.8 The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘show… wordfence
13d9a59f-1a1a-4936-a5ab-8a5e0c50303b
< 3.1.16
HIGH 8.8 The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized… wordfence
13d31af8-c606-4c83-be15-4446c4f330aa
< 2.5.6
HIGH 8.8 SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to… wordfence
13b5292f-4484-498b-b6b7-2895871ab794
< 3.1
HIGH 8.8 The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3… wordfence
13968257-593d-433e-9583-5bb5d6c6b2d5
< 2.3.16
HIGH 8.8 The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF. wordfence
1375ac68-31e4-4473-9757-bd86411c716f
< 1.9.9
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attacker… wordfence
136bf4c5-5309-479e-8d6b-f8a7334da9b0 HIGH 8.8 The WP CSV to Database plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
13348eb5-5001-4ec4-bc6a-44795bbed203 HIGH 8.8 The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in th… wordfence
130759b9-dc5d-4b0b-a0af-84e750b9b18b
< 1.2
HIGH 8.8 The User Management plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
12f7f9a0-96b0-4a61-b763-12ff679bf43d HIGH 8.8 The Coru LFMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0… wordfence
12d7a152-90cd-4c92-90c4-81c594e6c9ac
< 1.1.6
HIGH 8.8 The Booking Ultra Pro plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on mo… wordfence
12d370c8-ab17-4f84-8b1b-224a30802753 HIGH 8.8 The Bimber - Viral Magazine WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up… wordfence
12b4d9e6-761f-4857-a701-7d22d4ee0288
< 1.5.2
HIGH 8.8 The Make, formerly Integromat Connector plugin for WordPress is vulnerable to arbitrary options updates in versions up t… wordfence
12adf619-4be8-4ecf-8f67-284fc44d87d0
< 3.92.1
HIGH 8.8 The Automatic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.92.0.… wordfence
12849d7e-1685-4e03-be0c-0672545fcd2b
< 4.0.3
HIGH 8.8 The Express Shop plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.… wordfence
1281a4d8-fa77-45b4-b0b4-e3bed1b4a4ea HIGH 8.8 The Euclid Theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions. This is due to missing or in… wordfence
12560b8e-9c47-4f7f-ac9c-d86f17914ba3
< 1.1.2
HIGH 8.8 The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions starting from 1.0.7 … wordfence
123e1758-3384-4ea7-96dd-d6adcce40392
< 3.29.3
HIGH 8.8 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions … wordfence
123c2958-3335-4212-8ed0-b2a56a5272f3
< 6.0.1
HIGH 8.8 The OSM - OpenStreetMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
121d5d4d-cf15-4c20-afb5-aa3375f2ef62 HIGH 8.8 The Limb Gallery | Create Beautiful Image & Video Galleries plugin for WordPress is vulnerable to arbitrary file uploads… wordfence
← Prev 202 203 204 205 206 207 208 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top